Keyorix is an open-source secrets manager designed to run entirely on a company's own infrastructure. It stores the database passwords, API keys, and tokens that applications need, keeping them out of config files and source code. The tool ships as one binary and, in its core form, requires no internet connection, which the company behind it, Keyorix SL, pitches to teams that cannot send credentials to a cloud service.

The target audience includes air-gapped networks and European enterprises that need to align with NIS2 and DORA, the EU's security and financial-resilience rules. Keyorix's own comparison table positions it against Vault, which runs on premises but needs a dedicated admin, and Doppler, which is simple but SaaS-only. Developers can inject secrets as environment variables through a command-line tool or use SDKs for Go, Python, and Node.js, and teams already on Vault can import existing data.

Around the core are access controls, secret versioning, separate development, staging, and production environments, service tokens for CI/CD jobs, and dashboard alerts for secrets nearing rotation. A web dashboard provides a graphical interface. Under the hood, secret values are encrypted with AES-256-GCM, and a passphrase set at startup is stretched into a key-encrypting key that lives only in memory and wraps the data key. Data is stored in SQLite for development and small teams or PostgreSQL for production, and every access is logged with who, what, when, and from where. Keyorix is available for free on GitHub.